Win32.wom..trl

Here is a sample of the worm that has infected a USB drive and then infected another computer. I thought I had autoplay turned off, but that didn't stop the computer from getting infected. Bitdefender Internet Security 2009 says its the Win32.worm.trl but it only detects the autorun.inf file, not the executable that goes along with it, the system.exe. This apparently attaches itself to the services.exe in a kernel32.dll thread. I was able to locate which thread was kill the thread causing the constant infection of devices by detecting which thread was writting to the a drive. The sample file contains both the autorun.inf file and the system.exe file. I have the computers that are infected disconnected from my network but need a removal tool.

/applications/core/interface/file/attachment.php?id=4693" data-fileid="4693" rel="">system.zip

Comments